← Consultancy
Penetration testing as a service

Pentesting that lives in your dashboard, not a PDF

Expert-led manual testing delivered through our client portal. Request tests on demand, see findings the moment they’re confirmed, work with the tester in each finding and retest in one click.

Manual, not scanner-onlyLive in your dashboardOn-demand retestsCompliance-ready reports
Pentest portal · FindingsENG-2026-031
CRITICALPT-014 · Web app
Invoice API returns other customers’ invoices by changing one ID Chained with a weak session timeout, an attacker could export every invoice in under an hour.
Tue 14:02Found and confirmed by tester
Tue 14:20Live in your portal, owner notified
Thu 10:15Fix deployed by your developers
Thu 16:40Retest passed · Finding closed
Pentesting as a service

Your whole testing programme, in one dashboard

Request tests, watch findings arrive, talk to the tester, assign fixes and trigger retests, all in one client portal. No PDFs to chase, no email threads to lose.

Live findings Tester chat One-click retest Ticketing sync
Touchpoint · Pentest portal · Penetration testing Meridian Group
Overview Engagements3 Findings23 Retests4 Reports6 Scope from your attack surface41 + Request a test
Open findings 9 1 critical · 3 high
Median time to fix 6 days Critical and high
Ready for retest 4 Tester notified
Closed this quarter 14 Verified by retest
IDSeverityFindingOwnerStatus
PT-014 CRITICAL Invoice API returns other customers’ invoices (IDOR) A. Patel Ready for retest
PT-011 HIGH Kerberoastable service account with domain admin rights IT Ops Fix in progress
PT-017 HIGH Password reset token does not expire Unassigned Open
PT-009 MEDIUM Verbose stack traces expose framework version Web team Fix in progress
PT-006 HIGH Storage bucket readable without authentication Cloud team Closed
PT-014 · Thread Tester · Confirmed on /api/v2/invoices/{id}. Any authenticated user can read other tenants’ invoices. You · Fix is on staging. Can you check before we ship? Retest requested ✓
Engagement · Customer portal
Day 4 of 6 · Web app and API in progress Next: internal network, starts Monday
Illustrative dashboard with example data.
Request tests on demand Pick targets, choose dates and submit. No SOW back-and-forth.
Findings as they land Each finding appears the moment a tester confirms it, with evidence and fix guidance.
Talk to the tester Every finding has its own thread, so questions get answered by the person who found it.
Assign and sync Assign owners and push findings to Jira, ServiceNow or Azure DevOps. Status syncs back.
One-click retest Mark a fix ready and the tester verifies it. Closed findings are evidenced automatically.
Trends over time Time to fix, recurring issues and coverage across every engagement, not just the latest one.
Reports on demand Executive summary, technical report and retest letter, downloadable at any time.
One place for every test Every engagement, finding and retest in one place, across years of testing.
Why it's different

Most pentests end with a PDF. Ours end with the fix confirmed.

The usual way With Touchpoint
Findings arrive in a PDF weeks after testing ends Findings appear in your portal the day they’re confirmed
Scope is guessed from a questionnaire Scope is built from your real attack surface, so time goes where you’re actually exposed
Booking a test means weeks of emails and a new SOW Request a test from the dashboard; scope and schedule agreed in the same place
Questions go to a shared inbox and wait Talk to the tester directly inside each finding
Retesting is a new engagement and a new invoice Request a retest in one click when a fix ships
A list of vulnerabilities, ranked by CVSS Attack paths that show how weaknesses chain together, ranked by business impact
The report is filed and forgotten Every finding has an owner and a status until it’s retested and closed
What we test

Every surface an attacker would try

Web applications Authentication, access control, business logic, injection and session handling, against OWASP Top 10 and beyond.
APIs REST and GraphQL: broken object-level authorisation, mass assignment, rate limits and token handling.
External infrastructure Everything internet-facing: VPNs, mail, remote access, forgotten hosts and exposed services.
Internal network & Active Directory An assumed-breach test: lateral movement, privilege escalation and paths to domain admin.
Cloud AWS, Azure and Google Cloud: identity abuse, privilege escalation and exposed storage.
Social engineering Targeted phishing and vishing to test people and processes.
How it works

From scope to confirmed fix

  1. 01 Scope We agree targets, rules of engagement and timing, focused on where you’re actually exposed.
  2. 02 Test Senior testers work manually, chaining weaknesses the way a real attacker would.
  3. 03 Report live Each finding lands in your portal with evidence, impact and fix guidance as soon as it’s confirmed.
  4. 04 Fix Your team fixes, or our engineers implement it under a separate scope. Questions answered in the finding thread.
  5. 05 Retest We verify every fix and update the report.
What you get

Everything an auditor, customer or board will ask for

One engagement produces the evidence different audiences need, from a one-page summary for leadership to reproduction steps for developers.

✓ Executive summaryRisk in plain language, for leadership, customers and insurers.
✓ Technical findingsEvidence, reproduction steps, impact and fix guidance for each finding.
✓ Attack-path narrativeHow individual weaknesses combine into real routes to your data.
✓ Retest letterConfirmation of fixed findings, ready to share with customers.
✓ Compliance mappingFindings mapped to SOC 2, ISO 27001, PCI DSS and NIST CSF.
✓ Findings portalEvery finding owned, tracked and risk-ranked until it’s closed.
Engagement options

Three ways to buy pentesting as a service

Per engagement On-demand test For annual assurance, a customer requirement or a new release.
  • ✓Requested and scoped in the dashboard
  • ✓Live findings and tester chat
  • ✓One free retest per finding
  • ✓Full report and retest letter
Get a fixed quote →
Most flexible PTaaS subscription A bank of testing days for the year, used whenever you need them.
  • ✓Book tests from the dashboard any time
  • ✓New features tested as they ship
  • ✓Unlimited retests during the term
  • ✓Quarterly trend report for leadership
Get a fixed quote →
Assumed breach Internal & AD test For organisations that want to know how far one compromised laptop gets.
  • ✓Starts from a standard user account
  • ✓Lateral movement and privilege escalation
  • ✓Detection gaps reported to your SOC
  • ✓Hardening plan for Active Directory
Get a fixed quote →
Questions

Before you ask

What is pentesting as a service?+

The same expert manual testing, delivered through a platform instead of email and PDFs. You request tests, see findings live, talk to testers, track fixes and retest in one place, and you can test as often as your environment changes.

How is this different from a vulnerability scan?+

Scanners find known issues. Our testers find how issues combine: business logic flaws, broken access control and attack paths a scanner cannot see. A pentest goes deeper.

Will testing disrupt production?+

We agree rules of engagement up front, avoid destructive tests by default and can test against staging. We stop and call you if anything unexpected happens.

How much notice do you need?+

Usually two to three weeks from scope agreed to testing start, depending on the size of the engagement.

Do we need other Touchpoint services?+

No. Pentesting is a standalone service and works with whatever tools and providers you already use.

Find out what an attacker would find first

Tell us what you want tested. We’ll come back with a fixed-price scope, usually within two business days.

Scope a test
Other consultancy services Cloud security→ Tabletop exercises→ vCISO→ Engineering & implementation→